๐ฉ๐ช
Hazzard
2026-06-17 09:30:06
(1 week ago)
(wordpress) Failed wordpress login from 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (PH/Philippines/Provin ...
show more
(wordpress) Failed wordpress login from 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (PH/Philippines/Province of Batangas/Nasugbu/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-16 11:53:24
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (Unknown) ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 07:53:20.689710 2026] [security2:error] [pid 21440:tid 21440] [client 2001:fd8:ca2e:fb00:f002:7675:75be:9a9:61166] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ardeeapps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ardeeapps.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajE5MPNZBB33tUGgOXtWmQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-16 10:07:02
(1 week ago)
Automated web scanner. Requested suspicious paths: /xmlrpc.php. UTC: 2026-06-16 09:22:11.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 09:26:10
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (Unknown) ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:26:06.107480 2026] [security2:error] [pid 3446:tid 3446] [client 2001:fd8:ca2e:fb00:f002:7675:75be:9a9:59570] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paleopathologist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paleopathologist.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai_FLikp_TuiV15RovO2vgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ผ
ip4.tw
2026-06-15 05:15:01
(1 week ago)
Malicious web scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 05:46:47
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (Unknown) ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 01:46:41.766048 2026] [security2:error] [pid 29697:tid 29697] [client 2001:fd8:ca2e:fb00:f002:7675:75be:9a9:62670] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||isslv.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "isslv.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ai5AQdDKHHvmXWPR9-wz1wAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 22:35:00
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (Unknown) ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 18:34:52.731728 2026] [security2:error] [pid 4904:tid 4904] [client 2001:fd8:ca2e:fb00:f002:7675:75be:9a9:56755] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||desertautoworks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "desertautoworks.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai3bDHlDk54ok7ptIHR_VgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 07:02:40
(2 weeks ago)
Attac
Brute-Force
๐ฎ๐น
VHosting
2026-06-12 11:30:03
(2 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 09:31:57
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (Unknown) ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 05:31:51.573570 2026] [security2:error] [pid 30769:tid 30769] [client 2001:fd8:ca2e:fb00:f002:7675:75be:9a9:50980] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mavikalem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mavikalem.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aivSBy5qVYu-Bs7BXiAV-AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 02:48:52
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (Unknown) ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:fd8:ca2e:fb00:f002:7675:75be:9a9 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 22:48:44.519604 2026] [security2:error] [pid 21488:tid 21488] [client 2001:fd8:ca2e:fb00:f002:7675:75be:9a9:57405] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dwightbrown.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dwightbrown.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aitzjLCCmygOMbWX9DdBiwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-11 06:45:04
(2 weeks ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack